LGPD
How Sellio meets the LGPD (Brazil).
Last updated: July 2, 2026 · SellioCRM, LLC
Language
This document is provided in English, which is the authoritative version; any translation is for convenience only and the English version prevails.
This document applies to the customer relationship management software-as-a-service platform, websites, applications, APIs, software, documentation, dashboards, reports, artificial intelligence features, support, and related services made available by SellioCRM, LLC, a limited liability company.
For purposes of this document, "SellioCRM," "Company," "we," "us," and "our" mean SellioCRM, LLC. "Customer," "you," and "your" mean the person or entity accessing or using the Services. If you access or use the Services on behalf of an organization, you represent and warrant that you have authority to bind that organization, and that organization is the Customer.
This document is incorporated into and forms part of the SellioCRM Terms of Service unless expressly stated otherwise.
This document explains how SellioCRM approaches Brazil's Lei Geral de Protecao de Dados Pessoais (LGPD) and related guidance from the Autoridade Nacional de Protecao de Dados (ANPD). It is provided for transparency and does not constitute legal advice. Customers should consult their own counsel to determine how the LGPD applies to their organization and use of the Services.
1. Scope
This document applies where SellioCRM processes personal data subject to the LGPD in connection with the Services.
2. Roles Under the LGPD
Depending on the processing activity, SellioCRM may act as:
- a controller for its own business operations, such as account administration, billing, website analytics, marketing, security, usage metering, and customer relationship management
- an operator where SellioCRM processes Customer Personal Data on behalf of Customer through the Services
- an operator to another operator or service provider where Customer acts on behalf of a third-party controller
The Data Processing Addendum governs SellioCRM's operator obligations for Customer Personal Data where applicable.
3. Customer Responsibilities
Customer is responsible for determining the purpose and lawful basis for processing Customer Personal Data submitted to the Services, including CRM data relating to leads, contacts, prospects, customers, representatives, communications, notes, files, and activities. Customer is responsible for transparency notices, data subject rights, consents where required, records, security measures under Customer's control, retention decisions, opt-outs, communication preferences, and compliance with LGPD obligations applicable to Customer.
4. Legal Bases
Where SellioCRM acts as controller, it may rely on legal bases available under the LGPD, such as performance of contract, legitimate interest, consent, compliance with legal or regulatory obligations, exercise of rights in legal proceedings, protection of credit, or other lawful bases applicable to the processing.
5. Data Subject Rights
LGPD rights may include confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about sharing, information about consent consequences, revocation of consent, and review of certain automated decisions where applicable. Where SellioCRM processes Customer Personal Data as operator, Customer is generally responsible for responding to data subject requests, and SellioCRM will provide reasonable assistance as required by the DPA and applicable law.
6. International Transfers
SellioCRM is based in the United States and may process personal data in the United States and other countries. Where LGPD international transfer requirements apply, SellioCRM and Customer will cooperate in good faith to use appropriate transfer mechanisms, which may include ANPD standard contractual clauses, equivalent contractual clauses, specific contractual clauses, binding corporate rules, adequacy decisions, or other mechanisms recognized under the LGPD and ANPD regulations.
7. Security Measures
SellioCRM implements commercially reasonable technical and organizational measures designed to protect personal data. Customer remains responsible for account configuration, Authorized Users, connected systems, exports, communications, and Customer-controlled security measures.
8. Security Incident Notification
SellioCRM will notify Customer of confirmed Security Incidents affecting Customer Personal Data as required by the DPA and applicable law. Customer is responsible for assessing notification obligations to the ANPD, Data Subjects, customers, or other parties.
9. Sensitive Personal Data
Customer should avoid submitting sensitive personal data unless necessary, lawful, and permitted. Customer is responsible for determining whether sensitive personal data is involved and for implementing appropriate safeguards and lawful bases.
10. Automated Decisions and AI Features
AI Features may assist CRM workflows but do not make final legally significant decisions. Customer is responsible for reviewing AI outputs, providing required notices, honoring rights, and complying with LGPD requirements relating to automated decisions where applicable.
11. Retention and Deletion
Retention and deletion are described in the Terms of Service, Privacy Policy, and DPA. Customer controls retention of many categories of Customer Content and should export data before account closure or termination.
12. Contact
LGPD-related inquiries may be sent to legal@selliocrm.com.